We have discovered 2,695,348 live websites that are affected by CWE-269.
| 703,965 websites | |
| 356,348 websites | |
| 158,360 websites | |
| 113,594 websites | |
| 112,738 websites | |
| 95,772 websites | |
| 89,378 websites | |
| 82,326 websites | |
| 73,790 websites | |
| 66,860 websites |
| .com | 1,023,904 websites |
| .de | 221,280 websites |
| .org | 129,632 websites |
| .net | 92,626 websites |
| .nl | 89,453 websites |
| .it | 73,806 websites |
| .ru | 63,768 websites |
| .fr | 57,919 websites |
| .cz | 56,576 websites |
| .co.uk | 46,903 websites |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| Aug, 2026 | CVE-2026-13415 | CMP - Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_import_settings | 672 |
| Aug, 2026 | CVE-2026-19220 | Forminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege Escalation | 74,388 |
| Aug, 2026 | CVE-2026-75977 | Mang Board WP <= 2.3.7 - Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie | 318 |
| Aug, 2026 | CVE-2026-75971 | ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes | 4,800 |
| Aug, 2026 | CVE-2026-19222 | Forminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Role Bypass | 74,388 |
| Aug, 2026 | CVE-2026-18776 | TrueBooker Appointment Booking < 1.2.7 - Unauthenticated Account Takeover via Multiple AJAX Actions | 83 |
| Aug, 2026 | CVE-2026-18432 | Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter | 1,436 |
| Aug, 2026 | CVE-2026-15142 | Real Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision | 2 |
| Aug, 2026 | CVE-2026-15312 | Propovoice: All-in-One Client Management System <= 1.7.8 - Authenticated (ndpv_manager+) Privilege Escalation via 'role' Parameter | 2 |
| Aug, 2026 | CVE-2026-18039 | Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment | 255,495 |
| Discovered | CVE | Description | Websites |
|---|---|---|---|
| May, 2026 | CVE-2026-24072 | Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr | 1,693,773 |
| Jun, 2026 | CVE-2026-44119 | Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules | 1,577,765 |
| Aug, 2026 | CVE-2026-18039 | Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment | 255,495 |
| Jul, 2026 | CVE-2026-12525 | Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator | 209,828 |
| May, 2026 | CVE-2026-5193 | Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_user | 116,381 |
| Aug, 2026 | CVE-2026-19220 | Forminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege Escalation | 74,388 |
| Aug, 2026 | CVE-2026-19222 | Forminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Role Bypass | 74,388 |
| Mar, 2026 | CVE-2026-1993 | ExactMetrics 7.1.0 - 9.0.2 - Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update | 50,894 |
| Jul, 2026 | CVE-2026-12497 | ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection | 30,857 |
| Jul, 2026 | CVE-2026-12251 | Ultimate Member < 2.12.1 - Unauthenticated Privilege Escalation via Role Selection Field | 30,394 |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.com | ** | ||
| *************.***.****.****.************.net | *** | ||
| *****.***********.com | *** | ||
| ********.****.com | *** | ||
| *********.net | *** | ||
| ****************.net | *,*** | ||
| *****.cz | *,*** | ||
| ***.****.us | *,*** | ||
| ***.*********.com | *,*** | ||
| *****.*******.com | *,*** |